πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-41356 β€Ό

Windows Denial of Service Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42323 β€Ό

Azure RTOS Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-26444, CVE-2021-42301.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-31853 β€Ό

DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Apache Storm maintainers patch two pre-auth RCE vulnerabilities πŸ—“οΈ

High-risk issues were discovered by GitHub’s in-house security team

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-34598 β€Ό

In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-39474 β€Ό

Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker with privileges and network access through the ping.cmd component to execute commands on the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43136 β€Ό

An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-34582 β€Ό

In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25974 β€Ό

In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a Ò€œpublisherҀ� role is able to inject and execute arbitrary JavaScript code while creating a page/article.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25975 β€Ό

In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with Ò€œpublisherҀ� role to inject malicious JavaScript via the uploaded html file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Dark Reading Video News Desk Comes to Black Hat Europe πŸ•΄

While attendees join Black Hat Europe 2021 virtually and live in London, we bring you prerecorded interviews from remote offices around the world.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Black Hat Europe: Laws and regulations need to change to secure world’s digital infrastructure πŸ—“οΈ

Better incentives to build secure products needed, former MEP tells conference

πŸ“– Read

via "The Daily Swig".
❌ New Android Spyware Poses Pegasus-Like Threat ❌

PhoneSpy already has stolen data and tracked the activity of targets in South Korea, disguising itself as legitimate lifestyle apps.

πŸ“– Read

via "Threat Post".
πŸ•΄ Researcher Details Vulnerabilities Found in AWS API Gateway πŸ•΄

AWS fixed the security flaws that left the API service at risk of so-called HTTP header-smuggling attacks, says the researcher who discovered them.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 4 Tips to Secure the OT Cybersecurity Budget You Require πŸ•΄

OT security engineers and personnel should approach senior management with an emphasis on risk reduction benefits and with a concrete plan to secure budget and funding before it's too late.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Securing the Public: Who Should Take Charge? πŸ•΄

International policy expert Marietke Schaake explores the intricacies of protecting the public as governments depend on private companies to build and secure digital infrastructure.

πŸ“– Read

via "Dark Reading".
🦿 How healthcare organizations and patients are increasingly at risk from cyber threats 🦿

A majority of IT pros working at hospitals who were surveyed by Armis said they've seen a rise in cyber risk over the past 12 months.

πŸ“– Read

via "Tech Republic".
πŸ•΄ CISA and State and Local Partners Test Emergency Response Plans at Chevron Salt Lake Refinery πŸ•΄

The exercise included several objectives related to response procedures at the refinery, including evacuation and shelter-in-place decision-making; roles and responsibilities during investigations; communication with first responders; and public messaging before and following an incident.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Smuggling hidden backdoors into JavaScript with homoglyphs and invisible Unicode characters πŸ—“οΈ

Researchers urge developers to secure code by disallowing non-ASCII characters

πŸ“– Read

via "The Daily Swig".
❌ Massive Zero Day Hole Found in Palo Alto Security Appliances ❌

Researchers have a working exploit for the vulnerability (now patched), which allows for unauthenticated RCE and affects an estimated 70,000+ VPN/firewalls.

πŸ“– Read

via "Threat Post".
⚠ Sophos 2022 Threat Report: Malware, Mobile, Machine learning and more! ⚠

The crooks have shown that they're willing to learn and adapt their attacks, so we need to make sure we learn and adapt, too.

πŸ“– Read

via "Naked Security".